Fiche vulnérabilité
CVE-2021-25070 : faille critique stopbadbots block and stop bad bots (CVSS 9.8)
Description
The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 28 mars 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- stopbadbots block and stop bad bots